Azure MCP
Microsoft's official MCP server for Azure: 276 tools across 57 services at the 2.0 launch, including Cosmos DB, SQL, Storage, Key Vault, AKS and Monitor
BestMCPTools
Azure MCP
bestmcptools.org
Last verified: September 29, 2026
Maintenance status
ActiveStable 2.0.5 (July 10, 2026); 3.0 in beta (3.0.0-beta.47, Sept 24, 2026). Moved from the archived Azure/azure-mcp repo to microsoft/mcp.
How to Install Azure MCP
$npx -y @azure/mcp@2.0.5 server startRequires Claude Desktop, Cursor, Windsurf, or another MCP-compatible client.
Setup by client
Claude Desktop (claude_desktop_config.json)
{
"mcpServers": {
"azure-mcp": {
"command": "npx",
"args": [
"-y",
"@azure/mcp@2.0.5",
"server",
"start"
]
}
}
}Cursor (~/.cursor/mcp.json)
{
"mcpServers": {
"azure-mcp": {
"command": "npx",
"args": [
"-y",
"@azure/mcp@2.0.5",
"server",
"start"
]
}
}
}VS Code (.vscode/mcp.json)
{
"servers": {
"azure-mcp": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"@azure/mcp@2.0.5",
"server",
"start"
]
}
}
}Claude Code (terminal)
claude mcp add azure-mcp -- npx -y @azure/mcp@2.0.5 server startAdd any API keys or environment variables the server's README lists.
About Azure MCP
Azure MCP Server is Microsoft's official, open-source (MIT) Model Context Protocol server for Azure. It lets an AI agent in VS Code, Visual Studio, Cursor, Claude Code, Claude Desktop or any other MCP client list, query and manage Azure resources using your own Entra ID sign-in. The server is free; you pay only for the Azure resources it touches. The current stable release is 2.0.5 (July 10, 2026), and a 3.0 beta is in active development.
Quick facts (as of September 29, 2026)
| Azure MCP Server | |
|---|---|
| Maker | Microsoft (Azure SDK team) |
| Source code | github.com/microsoft/mcp, folder servers/Azure.Mcp.Server |
| License | MIT |
| Price | Free. Normal Azure charges apply to the resources you query or change. |
| Latest stable | 2.0.5 (npm, NuGet and PyPI, July 10, 2026) |
| Latest preview | 3.0.0-beta.47 (npm and NuGet, September 24, 2026) |
| Scope at 2.0 launch | 276 tools across 57 Azure services (Microsoft, April 10, 2026) |
| Packages | npm @azure/mcp, NuGet Azure.Mcp, PyPI msmcp-azure, Docker mcr.microsoft.com/azure-sdk/azure-mcp, .mcpb bundles |
| Authentication | Entra ID through the Azure Identity SDK (Azure CLI, VS Code, Visual Studio, Azure PowerShell, azd, service principal, managed identity) |
| Transports | stdio (local) and HTTP (self-hosted remote, the focus of the 2.0 release) |
| Clouds | Azure Public, Azure China, Azure US Government |
| Old repo | Azure/azure-mcp is archived (read-only); development moved to microsoft/mcp |
What it does
The server turns Azure operations into MCP tools. You ask your agent something like "list my storage accounts in resource group rg-prod" or "run this KQL query against my Data Explorer database" and the agent calls the matching tool, which runs against Azure with your identity and your RBAC permissions. It never gets more access than the account it signs in as.
Microsoft groups the tools by service. The README lists these areas, among others:
- Data: Cosmos DB, Azure SQL Database, SQL Server and Elastic Pools, Database for PostgreSQL, Database for MySQL, Azure Data Explorer (Kusto), Redis, Storage (blob) and File Shares
- Compute and apps: App Service, Functions, Container Apps, Azure Kubernetes Service, Virtual Machines and scale sets, Container Registry, Virtual Desktop
- Messaging and events: Service Bus, Event Grid, Event Hubs, SignalR
- Security and governance: Key Vault (secrets, keys, certificates), RBAC, Policy, Confidential Ledger, Quota, Subscriptions and Resource Groups
- Operations: Azure Monitor (logs and metrics), Managed Grafana, Workbooks, Service Health, Advisor, Backup, Load Testing, Azure SRE Agent
- AI: Microsoft Foundry (models, deployments, agents, knowledge indexes), Azure AI Search, Speech
- Infrastructure as code and guidance: Bicep, Azure Terraform and Terraform best practices, Azure CLI command generation, Well-Architected Framework, Cloud Architect, Retail Pricing lookups
The exact list changes between releases, so check the README for the version you install.
Cosmos DB tools
The Cosmos DB tools are all read-only: list accounts, databases and containers; run a SQL-API query against a container; get one item by ID; list the most recently modified items; full-text search (requires a full-text index); vector similarity search (requires a vector index on the container and an Azure OpenAI embedding deployment); and infer a container's schema from sampled documents. You cannot create or delete Cosmos DB data through these tools.
Azure Data Explorer (Kusto) tools
The Data Explorer tools are also read-only: list clusters, get cluster details, list databases, list tables, get a table schema, sample rows, and run a KQL query. You can point them at a cluster URI, or at a cluster name plus subscription. If you searched for an "Azure Kusto MCP server", this is Microsoft's official option.
Azure Data Factory
Azure Data Factory is not in the Azure MCP Server's service list. Microsoft publishes a separate server, microsoft/DataFactory.MCP, but it targets Microsoft Fabric Data Factory, not classic Azure Data Factory. It ships as the NuGet package Microsoft.DataFactory.MCP, needs .NET 10, and marks several of its tools as preview. Microsoft does not list a server for classic Azure Data Factory.
Azure MCP Server 2.0 and 3.0
Microsoft announced Azure MCP Server 2.0 as a stable release on April 10, 2026. The main changes it listed:
- Self-hosted remote server. The server can now run as a remote MCP server over HTTP so a team or an agent platform shares one deployment. Microsoft's README suggests Azure Container Apps for hosting and names Microsoft Foundry and Copilot Studio as clients that need an HTTP server; its authentication guide requires an Entra ID bearer token on every inbound request.
- New auth options for remote use: managed identity when running alongside Microsoft Foundry, and an On-Behalf-Of flow so calls run as the signed-in user.
- Security hardening: stronger endpoint validation, protection against injection patterns in query tools, and tighter isolation.
- Sovereign clouds (Azure US Government, Azure China), smaller container images and more distribution options.
Patch releases followed through 2.0.5 on July 10, 2026. Microsoft started publishing 3.0.0 betas on npm on April 1, 2026 and has kept shipping them: 3.0.0-beta.47 came out on September 24, 2026. We found no announced date for a 3.0 stable release.
One thing to watch: on npm the latest tag currently points to 3.0.0-beta.47, not to 2.0.5. Microsoft's own configs use @azure/mcp@latest, so if you copy them you get the beta. If you want the stable line, pin the version, for example @azure/mcp@2.0.5. On PyPI, msmcp-azure is at 2.0.5.
How to install it
Sign in to Azure first (az login works for every method). The server picks up your existing credentials; there is no API key to paste.
VS Code (Microsoft's recommended path)
- Install the GitHub Copilot Chat extension.
- Install the Azure MCP Server extension (
ms-azuretools.vscode-azure-mcp-server) from the Visual Studio Marketplace. - Run Azure: Sign In from the Command Palette.
- Open Copilot Chat in Agent mode and refresh the tools list.
The extension has settings for server mode, which services to expose, and a read-only switch (azureMcp.readOnly).
Any client that takes a JSON config (Cursor, Windsurf, Cline, Claude Desktop manual config)
Microsoft's config, which requires Node.js LTS:
{
"mcpServers": {
"azure-mcp-server": {
"command": "npx",
"args": ["-y", "@azure/mcp@latest", "server", "start"]
}
}
}
Replace @latest with @2.0.5 to stay on the stable release. Config file locations from Microsoft's README: Cursor ~/.cursor/mcp.json or .cursor/mcp.json; Windsurf ~/.codeium/windsurf/mcp_config.json; VS Code .vscode/mcp.json; Claude Desktop claude_desktop_config.json.
Claude Desktop (no Node.js needed)
Microsoft publishes .mcpb bundles for Windows, macOS and Linux (x64 and ARM64) on the GitHub Releases page. Download the one for your machine and drag it into the Claude Desktop window. The bundle contains the server and its dependencies, so you do not need Node.js or .NET.
Claude Code
Microsoft's README points Claude Code users to the Azure plugin, which bundles the server with Azure agents and skills:
/plugin install azure@claude-plugins-official
You can also add the server on its own with Claude Code's standard command:
claude mcp add azure-mcp -- npx -y @azure/mcp@latest server start
Visual Studio, IntelliJ, Eclipse, GitHub Copilot CLI
In Visual Studio 2026, select the Azure and AI development workload with GitHub Copilot in the Visual Studio Installer. In Visual Studio 2022, Microsoft's README says to install the GitHub Copilot for Azure extension, while the Learn overview says version 17.14.30 and later include the Azure MCP tools in the Azure development workload with no separate extension. IntelliJ uses the GitHub Copilot plugin plus the Azure Toolkit for IntelliJ, and Eclipse uses the GitHub Copilot plugin plus the Azure Toolkit for Eclipse. In GitHub Copilot CLI, run /mcp add and enter npx -y @azure/mcp@latest server start as a local command.
Python, .NET and Docker
- Python:
uvx --from msmcp-azure azmcp server start - .NET 10:
dnx Azure.Mcp --source https://api.nuget.org/v3/index.json --yes -- azmcp server start - Docker:
mcr.microsoft.com/azure-sdk/azure-mcp:latest, with service principal credentials (AZURE_TENANT_ID,AZURE_CLIENT_ID,AZURE_CLIENT_SECRET) passed in an env file.
Authentication
Locally, the server tries a chain of credentials and uses the first that works: environment variables (service principal), Visual Studio, VS Code, Azure CLI, Azure PowerShell, Azure Developer CLI, then an interactive browser login. You can pin one with AZURE_TOKEN_CREDENTIALS, for example AZURE_TOKEN_CREDENTIALS=AzureCliCredential. For CI, Microsoft recommends a service principal or, in Azure Pipelines, workload identity federation. For production hosting it recommends the HTTP transport; if you must use stdio there, AZURE_TOKEN_CREDENTIALS=prod removes the interactive browser fallback.
Whatever credential is used, the identity needs the right RBAC roles on the target resources (for example Storage Blob Data Reader to read blobs). The README states the server never stores or manages tokens itself; it relies on the Azure Identity SDK.
Server modes: controlling how many tools the agent sees
With 276 tools at the 2.0 launch, tool count matters. VS Code, for example, supports at most 128 tools across all MCP servers. The server offers several modes:
| Mode | What the agent sees |
|---|---|
namespace (default) | One tool per Azure service, which routes to that service's operations |
consolidated | Curated task-based tools, such as one for database details, well under 128 |
single | One azure tool that routes everything |
all | Every individual tool |
--namespace storage --namespace keyvault | Only the services you list |
--tool <name> | Only the specific tools you list |
Add --read-only to any mode to block write operations. Example: azmcp server start --mode namespace --read-only.
Security notes
- Least privilege matters most. Microsoft's README warns that autonomous or misconfigured clients may perform destructive actions and recommends reviewing and applying least-privilege RBAC roles. Start with
--read-onlyand a reader role, and widen only when you need to. - Telemetry is on by default and goes to Microsoft. Set
AZURE_MCP_COLLECT_TELEMETRY=falseto turn off all telemetry, orAZURE_MCP_COLLECT_TELEMETRY_MICROSOFT=falseto stop only Microsoft's stream. In the VS Code extension, VS Code's own telemetry setting applies. - Remote deployments require Entra ID bearer tokens on every inbound request. Microsoft provides azd templates for Azure Container Apps.
- Support logs can be written with
--dangerously-write-support-logs-to-dir. Microsoft documents it for advanced troubleshooting only. - The software is provided as is under MIT, and Microsoft's README puts compliance with your organization's rules on you.
Azure MCP Server vs other Microsoft MCP servers
Microsoft publishes several MCP servers, and they are easy to mix up.
| Server | What it covers | How you run it | Status |
|---|---|---|---|
| Azure MCP Server (this page) | Azure resources and services, 57 services at 2.0 | Local (npx, uvx, dnx, Docker, .mcpb, IDE extensions) or self-hosted HTTP | 2.0.5 stable; 3.0 in beta |
| Azure DevOps MCP | Work items, repos, pull requests, pipelines, test plans, wikis | Remote at https://mcp.dev.azure.com/{organization} (Microsoft's recommended option) or local npx -y @azure-devops/mcp {organization} | Remote server in preview; Microsoft says it will eventually replace the local one |
| Microsoft Learn MCP | Search and fetch official Microsoft documentation and code samples | Remote at https://learn.microsoft.com/api/mcp, no sign-in | Free, public |
| Microsoft Fabric MCP | Microsoft Fabric public APIs, item definitions and best practices, plus OneLake data operations | Local, from the same microsoft/mcp repo | Public preview |
| Fabric Data Factory MCP | Microsoft Fabric Data Factory pipelines and jobs | NuGet Microsoft.DataFactory.MCP (.NET 10) | Some tools in preview |
Rule of thumb: use Azure MCP Server for your cloud resources, Azure DevOps MCP for your code and delivery work, and add Microsoft Learn MCP when you want the agent to check current documentation. They work side by side. If your team manages Azure through Terraform, also look at HashiCorp's Terraform MCP; Azure MCP's AKS examples cover clusters and node pools, so for work inside a cluster, look at a Kubernetes MCP server.
Who it is for
A good fit if:
- Your team runs on Azure and wants agents to answer questions like "which storage accounts allow public access" or "show errors from the last hour in Log Analytics" without writing CLI commands.
- You already use GitHub Copilot in VS Code or Visual Studio, where setup is an extension install.
- You want one server across many Azure services instead of a separate community server per service.
- You need a shared, Entra-protected MCP endpoint for Foundry or Copilot Studio agents (2.0 remote mode).
Not the right tool if:
- You need Azure DevOps boards, repos or pipelines. Use Azure DevOps MCP.
- You need classic Azure Data Factory. It is not covered.
- You want to write to Cosmos DB or Data Explorer. Those tools are read-only.
- You cannot grant an AI client any Azure permissions. Even read access exposes resource names, settings and data.
What we don't know
- When 3.0 will be declared stable, and what will change from 2.0. Microsoft has published many betas but no 3.0 announcement.
- The exact tool count in the current release. The 276-tool, 57-service figure is from the 2.0 launch; the README's service list has grown since.
- Whether Microsoft plans a Microsoft-hosted Azure MCP endpoint like the one Azure DevOps offers. Today the remote option is self-hosted.
How this page was put together
We compared Microsoft's published material: the Azure MCP Server README and command reference on GitHub, the Microsoft Learn documentation, the Azure SDK blog's 2.0 announcement, and package data from npm, PyPI and NuGet, all checked on September 29, 2026. We did not run the server against a live Azure subscription. Version numbers and tool lists change often, so check the linked sources before relying on a detail.
Sources
- Azure MCP Server README, microsoft/mcp on GitHub
- Azure MCP command reference (server modes, read-only)
- Azure MCP authentication guide
- Microsoft Learn: Azure MCP Server overview
- Microsoft Learn: Get started with Azure MCP Server
- Microsoft Learn: Azure Cosmos DB tools
- Microsoft Learn: Azure Data Explorer tools
- Azure SDK Blog: Announcing Azure MCP Server 2.0 stable release
- npm: @azure/mcp
- PyPI: msmcp-azure
- NuGet: Azure.Mcp
- GitHub: Azure/azure-mcp (archived)
- GitHub: microsoft/azure-devops-mcp
- GitHub: microsoft/DataFactory.MCP
- Microsoft Learn MCP Server
Pricing
Open Source: from Free (Azure resource costs apply)
Our Take on Azure MCP
A strong first pick for teams on Azure: official, free, MIT-licensed and covering 57 services at the 2.0 launch, with Entra ID auth and a read-only mode. Pin @azure/mcp@2.0.5 if you want the stable release, because npm's latest tag currently installs the 3.0 beta. Use Azure DevOps MCP alongside it for repos, boards and pipelines.
Alternatives to Azure MCP
Let AI agents inspect and manage Kubernetes clusters
View Kubernetes MCP →HashiCorp's official MCP server for Terraform Registry and IaC workflows
View Terraform MCP →